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A special meeting of the COINS Committee was held in 
The Directors Conference Room at NSA Friday morning 22 
November. The Committee heard a presentation by 
on a threeit matrix they had devised, which could be used for 
a security evaluation of COINS (matrix attached) . 

The briefing was primarily an explanation of the terms 
used in the matrix and examples. It was not a plan for the 
security evaluation of COINS, but a methodology. One comment 
afterwards was that it was almost a glorified check list. 

agreed that the Committee would have to draw up 
its own security evaluation plan, probably using this as a 
guide. 

In the question and answer part of the program afterwards 
several interesting points were made. First of all, most of 
the S06 people thought that software was potentially the 
greatest security threat. They had found in their experience 
few hardware difficulties (e.g., false dumps through machine 
shortcomings) . They also refused to handle absolutes -- they 
could never at any point say that a system was really secure. 
They looked at themselves more like data gatherers (e.g., 
private detectives) who presented the facts to management 
and let management make the decision whether the system was 
safe. 
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